An open API service providing security vulnerability metadata for many open source software ecosystems.

go

github.com/fluxcd/flux2

go · Repository · Package

Moderate
almost 3 years ago

Improper use of metav1.Duration allows for Denial of Service GSA_kwCzR0hTQS1mNHA1LXg0dmMtbWg0ds4AAvcq

go github.com/fluxcd/source-controller/api, github.com/fluxcd/notification-controller/api, github.com/fluxcd/kustomize-controller/api, github.com/fluxcd/image-reflector-controller/api, github.com/fluxcd/image-automation-controller/api, github.com/fluxcd/helm-controller/api, github.com/fluxcd/image-reflector-controller, github.com/fluxcd/image-automation-controller, github.com/fluxcd/notification-controller, github.com/fluxcd/helm-controller, github.com/fluxcd/kustomize-controller, github.com/fluxcd/source-controller, github.com/fluxcd/flux2
High
about 3 years ago

Helm Controller denial of service GSA_kwCzR0hTQS1wMmc3LXh3dnItcnJ3M84AAu1q

go github.com/fluxcd/flux2, github.com/fluxcd/helm-controller
High
about 3 years ago

Flux CLI Workload Injection GSA_kwCzR0hTQS14d2YzLTZyZ3YtOTM5cs4AAulJ

go github.com/fluxcd/flux2
High
over 3 years ago

Improper path handling in Kustomization files allows for denial of service GSA_kwCzR0hTQS03cHdmLWpnMzQtaHh3cM4AAgbk

go github.com/fluxcd/flux2, github.com/fluxcd/kustomize-controller
Critical
over 3 years ago

Improper kubeconfig validation allows arbitrary code execution GSA_kwCzR0hTQS12dm1xLWZ3bWctMmdqY84AAX50

go github.com/fluxcd/helm-controller, github.com/fluxcd/kustomize-controller, github.com/fluxcd/flux2
Critical
over 3 years ago

Improper path handling in kustomization files allows path traversal GSA_kwCzR0hTQS1qNzdyLTJmeGYtNWpyd83fmw

go github.com/fluxcd/flux2, github.com/fluxcd/kustomize-controller